Last updated: March 2026
๐ฟ What we collect
Spillit is designed to collect as little as possible:
- Confession & reply content โ the text you post, stored in our database. It contains no information that identifies you unless you choose to include it yourself.
- An anonymous session token โ a random ID stored as a cookie in your browser (
spillit_sid). This is used only to prevent duplicate likes. It contains no personal data and cannot be used to identify you. - Your IP address โ used temporarily in memory for rate limiting (to prevent spam). It is never stored in our database.
- Category and timestamp โ when a confession is posted, we record its category and the time it was posted.
๐ซ What we don't collect
- Your name, email address, or phone number
- Your location or device information
- Your browsing history or activity outside Spillit
- Any account credentials โ there are no accounts
- Advertising identifiers or tracking pixels
๐ช Cookies
We use a single cookie: spillit_sid. It is:
- httpOnly โ JavaScript on the page cannot read it
- Signed โ tamper-evident, server-verified
- Anonymous โ a random UUID with no connection to your identity
- Long-lived โ expires after 1 year so your like preferences persist
We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
๐ฆ How data is used
The data we collect is used only to operate Spillit:
- Confession content is displayed publicly in the feed
- The session token is used to enforce one-like-per-person on confessions and replies
- Reaction and reply counts are public
- Reported confessions are reviewed by our admin for moderation
We never sell, share, or transfer your data to third parties for advertising or any commercial purpose.
๐๏ธ Data retention & deletion
- Confessions marked "Disappears in 24h" are automatically removed after 24 hours
- Other confessions remain until deleted by our admin team following a report
- Because confessions carry no identity, we cannot look up or delete posts by user โ if you need content removed, use the Report button on the confession
๐ Third-party services
Spillit uses Google Fonts to load typefaces. When the page loads, your browser makes a request to Google's servers. Google's privacy policy applies to that request. We use no other third-party services.
๐ถ Children's privacy
Spillit is intended for users aged 13 and over. We do not knowingly collect information from children under 13. If you believe a child has submitted content, please use the Report button or contact us.
โ๏ธ Contact
Questions about this privacy policy? Reach out at privacy@spillit.app. We'll do our best to respond within 5 business days.